Skip to content

Commit b59b501

Browse files
committed
Adding customer intents - mixed files
1 parent ef533b7 commit b59b501

File tree

71 files changed

+284
-0
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

71 files changed

+284
-0
lines changed

articles/sentinel/audit-sentinel-data.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,10 @@ author: limwainstein
55
ms.topic: how-to
66
ms.date: 01/09/2023
77
ms.author: lwainstein
8+
9+
10+
#Customer intent: [AI]As a security operations analyst, I want to audit queries and activities in my SOC environment so that I can ensure compliance and monitor security operations effectively.
11+
812
---
913

1014
# Audit Microsoft Sentinel queries and activities

articles/sentinel/audit-table-reference.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,10 @@ ms.author: lwainstein
66
ms.topic: reference
77
ms.date: 01/17/2023
88
ms.service: microsoft-sentinel
9+
10+
11+
#Customer intent: [AI]As a security analyst, I want to understand the schema and usage of Microsoft Sentinel audit tables so that I can effectively monitor and audit user activities within my SIEM environment.
12+
913
---
1014

1115
# Microsoft Sentinel audit tables reference

articles/sentinel/aws-s3-troubleshoot.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,10 @@ ms.author: lwainstein
66
ms.topic: troubleshooting
77
ms.date: 09/08/2022
88
#Customer intent: As a security operator, I want to quickly identify the cause of the problem occurring with the AWS S3 connector so I can find the steps needed to resolve the problem.
9+
10+
11+
#Customer intent: [AI]As a cloud security engineer, I want to troubleshoot AWS S3 connector issues so that I can ensure seamless log ingestion into my SIEM system.
12+
913
---
1014

1115
# Troubleshoot AWS S3 connector issues

articles/sentinel/best-practices-data.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,10 @@ author: limwainstein
55
ms.author: lwainstein
66
ms.topic: conceptual
77
ms.date: 01/09/2023
8+
9+
10+
#Customer intent: [AI]As a security operations analyst, I want to implement best practices for data collection using cloud-based SIEM connectors so that I can optimize log ingestion, reduce costs, and enhance security monitoring.
11+
812
---
913

1014
# Data collection best practices

articles/sentinel/best-practices-workspace-architecture.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,10 @@ author: limwainstein
55
ms.author: lwainstein
66
ms.topic: conceptual
77
ms.date: 06/28/2023
8+
9+
10+
#Customer intent: [AI]As a security architect, I want to design an optimal Log Analytics workspace architecture for my Microsoft Sentinel deployment so that I can meet business, compliance, and cost requirements while ensuring efficient data management and access control.
11+
812
---
913

1014
# Microsoft Sentinel workspace architecture best practices

articles/sentinel/cef-name-mapping.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,10 @@ author: yelevin
55
ms.author: yelevin
66
ms.topic: reference
77
ms.date: 08/12/2024
8+
9+
10+
#Customer intent: [AI]As a security analyst, I want to understand the mapping between CEF fields and CommonSecurityLog fields so that I can accurately interpret and analyze security events in my SIEM system.
11+
812
---
913

1014
# CEF and CommonSecurityLog field mapping

articles/sentinel/configure-content.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,10 @@ ms.topic: how-to
66
ms.date: 07/05/2023
77
ms.author: lwainstein
88
#Customer intent: As a SOC analyst, I want to configure the Microsoft Sentinel security content, so I can protect my organization against threats.
9+
10+
11+
#Customer intent: [AI]As a security operations analyst, I want to configure security content in my SIEM platform so that I can detect, monitor, and respond to security threats effectively.
12+
913
---
1014

1115
# Configure Microsoft Sentinel content

articles/sentinel/configure-data-retention-archive.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,10 @@ ms.topic: how-to
66
ms.date: 07/21/2024
77
ms.author: cwatson
88
#Customer intent: As a SOC analyst, I want to set up interactive and long-term data retention settings so I can retain the data that's important to my organization in the long term.
9+
10+
11+
#Customer intent: [AI]As a security analyst, I want to configure data retention and archiving policies so that I can ensure long-term storage of important data at a reduced cost.
12+
913
---
1014

1115
# Configure interactive and long-term data retention in Microsoft Sentinel

articles/sentinel/connect-azure-virtual-desktop.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,10 @@ author: limwainstein
55
ms.topic: how-to
66
ms.date: 01/09/2023
77
ms.author: lwainstein
8+
9+
10+
#Customer intent: [AI]As a security analyst, I want to monitor Azure Virtual Desktop environments using a SIEM solution so that I can enhance remote work capabilities while maintaining security.
11+
812
---
913

1014
# Connect Azure Virtual Desktop data to Microsoft Sentinel

articles/sentinel/connect-dns-ama.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,10 @@ ms.topic: how-to
66
ms.date: 01/05/2022
77
ms.author: lwainstein
88
#Customer intent: As a security operator, I want to proactively monitor Windows DNS activities so that I can prevent threats and attacks on DNS servers.
9+
10+
11+
#Customer intent: [AI]As a security analyst, I want to stream and filter DNS server logs using a cloud-based monitoring agent so that I can detect and mitigate potential threats efficiently.
12+
913
---
1014

1115
# Stream and filter data from Windows DNS servers with the AMA connector

0 commit comments

Comments
 (0)